Users were able to set an arbitrary... CVE-2023-26456

- AV AC AU C I A
发布: 2023-11-02
修订: 2024-01-12

Users were able to set an arbitrary "product name" for OX Guard. The chosen value was not sufficiently sanitized before processing it at the user interface, allowing for indirect cross-site scripting attacks. Accounts that were temporarily taken over could be configured to trigger persistent code execution, allowing an attacker to build a foothold. Sanitization is in place for product names now. No publicly available exploits are known.

0%
暂无可用Exp或PoC
当前有5条受影响产品信息